VDB
Sign up

package

Packagist/zendframework/zendframework1

pkg:packagist/zendframework/zendframework1

HIGH8.6Packagist
GHSA-229x-22xc-2f2w

Zendframework Local file disclosure via XXE injection in Zend_XmlRpc

Modified: 6/7/2024

HIGH7.5Packagist
GHSA-2jx7-xg83-j2m7

Zendframework Denial of Service vector via XEE injection

Modified: 6/7/2024

CRITICAL9.8Packagist
GHSA-2x36-qhx3-7m5f

ZendFramework1 Potential SQL injection in the ORDER implementation of Zend_Db_Select

Modified: 12/4/2024

HIGH7.5Packagist
GHSA-4j9x-g4x8-vcmf

ZendFramework potential XML eXternal Entity injection vectors

Modified: 12/4/2024

MEDIUM6.1Packagist
GHSA-4v57-pwvf-x35j

Zendframework potential Cross-site Scripting vector in `Zend_Service_ReCaptcha_MailHide`

Modified: 6/7/2024

MEDIUM6.1Packagist
GHSA-4vf6-mq7w-3hp6

Zend_Filter_StripTags vulnerable to Cross-site Scripting when comments allowed

Modified: 6/7/2024

CRITICAL9.8Packagist
GHSA-6fqw-j3vm-7f66

Zendframework1 Potential SQL injection in ORDER and GROUP functions

Modified: 12/4/2024

HIGH7.5Packagist
GHSA-848f-mph5-9pm9

Zendframework Potential Information Disclosure and Insufficient Entropy vulnerability

Modified: 12/4/2024

HIGH7.5Packagist
GHSA-8xhv-gqm4-3w99

ZendFramework1 Potential Insufficient Entropy Vulnerability

Modified: 12/4/2024

HIGH7.5Packagist
GHSA-9v78-h226-2rmq

Zendframework potential security issue in login mechanism

Modified: 12/4/2024

MEDIUM6.1Packagist
GHSA-g52p-86j5-xr8q

ZendFramework Potential Cross-site Scripting in Development Environment Error View Script

Modified: 6/7/2024

MEDIUM6.1Packagist
GHSA-gwpm-pm6x-h7rj

ZendFramework Cross-site Scripting vector in `Zend_Filter_StripTags`

Modified: 6/7/2024

MEDIUM6.1Packagist
GHSA-hg35-vqp3-fv39

ZendFramework potential Cross-site Scripting vectors due to inconsistent encodings

Modified: 6/7/2024

HIGH7.5Packagist
GHSA-hx3m-959f-v849

ZendFramework local file inclusion vector in `Zend_View::setScriptPath()` and `render()`

Modified: 6/7/2024

MEDIUM6.1Packagist
GHSA-j543-vg33-g6vj

ZendFramework potential Cross-site Scripting vector in `Zend_Dojo_View_Helper_Editor`

Modified: 6/7/2024

CRITICAL9.8Packagist
GHSA-mhpx-3rv8-wrjm

ZendFramework potential XML eXternal Entity injection vectors

Modified: 12/4/2024

CRITICAL9.8Packagist
GHSA-qf36-fx9f-232x

ZendFramework potential SQL Injection Vector When Using PDO_MySql

Modified: 6/7/2024

CRITICAL9.8Packagist
GHSA-v42g-7q2x-cw32

Zendframework1 potential SQL injection vector using null byte for PDO (MsSql, SQLite)

Modified: 12/4/2024

MEDIUM6.1Packagist
GHSA-vvm3-rv48-j3g5

Zendframework Potential XSS or HTML Injection vector in Zend_Json

Modified: 6/7/2024

MEDIUMPackagist
GHSA-w5mj-j45q-m638

ZendFramework1 Potential Security Issues in Bundled Dojo Library

Modified: 6/7/2024